CVE-2012-5697
The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which allows local users to obtain sensitive information or inject arbitrary…
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which allows local users to obtain sensitive information or inject arbitrary Perl code via direct access to these files.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- bulbsecurity/smartphone pentest framework
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/51415
- https://twitter.com/georgiaweidman/statuses/269138431567855618Vendor Advisory
- https://www.htbridge.com/advisory/HTB23123Exploit
- http://secunia.com/advisories/51415
- https://twitter.com/georgiaweidman/statuses/269138431567855618Vendor Advisory
- https://www.htbridge.com/advisory/HTB23123Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.